FreeFall • Antigravity Companion

BETA · UPDATED 6 OCTOBER 2026

Security, explained.

FreeFall connects your phone to a running PC. Approving a phone gives it access to Antigravity projects and agent tasks on that PC. A compromised approved phone or PC can expose your workspace.

Connection and access controls

Production connections use HTTPS/WSS. The companion connects outward to the relay, and its local control page listens only on the PC's loopback interface. Local control actions require a random secret and reject cross-origin requests.

Pairing codes expire in two minutes and are single-use. The PC must explicitly approve each phone. Pending approvals expire in five minutes; device access expires after 30 days. Revoking a phone denies subsequent access and cancels its active relay requests; it cannot undo actions already performed on the PC.

Device cookies use Secure, HttpOnly and SameSite=Strict. The relay stores hashes of PC/device bearer secrets. API origin checks reject cross-site requests. Request sizes and concurrent relay requests are bounded.

Android and updates

Android cleartext traffic, mixed web content, file access and app backup are disabled. QR links must be valid HTTPS pairing links, and the service address is shown before connecting. Camera permission is requested when scanning, and barcode images are not saved.

The APK is signed. Release metadata uses a pinned public key; companion updates require a valid signature, an approved download origin and matching file size/checksum. Automatic PC update installation is off by default. Updates back up companion code and restore it if startup health fails, retaining runtime and user state. Rollback was verified in an isolated failure fixture; clean-PC installation and actual startup recovery still need broader testing. Windows publisher signing is prepared but this beta EXE remains unsigned.

Optional app PIN

PIN lock is off by default. Enable it in Settings with a six-digit PIN. It protects FreeFall screens on launch and after the app goes into the background, including the interactive terminal. PIN entry and PIN-editing dialogs use Android’s secure-window flag. Workspace screenshots are allowed by default, and an optional setting blocks them while PIN lock is enabled.

The PIN itself is not stored. A salted PBKDF2 verifier is encrypted using an Android Keystore key. Five incorrect attempts trigger a 30-second cooldown, with longer cooldowns for further failures. Cooldown state persists across restarts. Changing or disabling the PIN requires the current PIN. Optional biometric unlock uses an authenticated Keystore cipher and retains PIN fallback. Optional paired-PC recovery must be enabled while unlocked after verifying the current PIN. The phone requests recovery, its owning PC explicitly approves it, and a grant expires after two minutes and can be used once. The replacement PIN is chosen locally on the phone and is never sent to the relay. Recovery trusts the paired PC and TLS relay. Without recovery enabled, clearing app data removes local settings and files.

This PIN is an app screen lock, not encryption of every workspace file or protection from a rooted/compromised device. It does not revoke PC access or protect the separate Termux app.

Shared files, alerts and diagnostics

File sharing is off until a folder is chosen locally on the PC. Approved phones may list, download and upload files in that folder, up to 8 MiB per file. Traversal and links are rejected; replacing an existing file requires confirmation. Disable sharing or pause phone access in the companion or tray menu.

Optional task alerts contain generic completion or approval text. They use accessible workspace status signals or explicit PC alerts and require FreeFall to stay open; no background push service is included. Diagnostic reports contain only app version, Android API, crash category and time. Reports are previewed and exported locally; they are not uploaded automatically.

Privacy and current limits

This beta is not end-to-end encrypted. The hosted relay can process workspace requests and responses. Pairing/device records are stored to operate access controls. We do not claim zero logging or independently verified privacy guarantees.

No independent penetration test or security certification has been completed. Automated tests cover pairing approval, replay rejection, expiry, credential boundaries, cross-site rejection, revocation and release-signature validation. Real-phone compatibility and wider desktop integration testing remain in progress. These tests do not guarantee that every vulnerability has been found.

Built-in console

The native console runs with FreeFall’s Android app permissions, starting in a private workspace. It has no root privileges and is not exposed to websites, QR links or incoming intents. Console output stays in memory until cleared or the app process ends; workspace files remain until removed or the app is uninstalled. Commands can modify any files the app can access. Stop session terminates the shell process group; programs that deliberately detach into another session may escape that control. Background execution is not guaranteed.

The interactive terminal reuses the terminal-emulator and terminal-view components from Termux v0.118.3 under the upstream Apache License 2.0 exception. FreeFall builds their native code from source; original notices are included in the app. It uses Android’s system shell, not a bundled Termux package environment.

Keep your devices safe

Use downloads linked from this website. Approve only your own phones, keep Android/WebView and the PC updated, and disconnect a lost phone in the PC companion. Optional Termux commands and AI-generated commands can change or delete files; review commands before running them.

Reporting an issue

If you suspect an issue, disconnect affected phones and stop the companion if needed. Contact the developer through the channel where you received the beta. Share the app version, steps and a screenshot with secrets removed. Never publish pairing QR codes, bearer tokens, API keys, private project files or executable exploit details. A dedicated private reporting address is not yet available.

Back to FreeFall ↖